Blog · C.33 · Compliance Guide

Qatar penetration testing requirements — QCB & the NIA Policy

Qatar has one of the most specific penetration testing mandates in the Gulf. The Qatar Central Bank requires banks to test twice a year; the National Information Assurance Policy sets government expectations. Here is exactly what each requires, in their own words.

QatarQCBNIA PolicyNCSABanking
Qatar: QCB Semi-Annual VAPT · Two Pen Tests / Year (Apps) · NIA IM 9 Annual Assurance Plan · SS 7 Independent Testing · NCSA Critical Sectors Qatar: QCB Semi-Annual VAPT · Two Pen Tests / Year (Apps) · NIA IM 9 Annual Assurance Plan · SS 7 Independent Testing · NCSA Critical Sectors
// TL;DR

Qatar's Qatar Central Bank (QCB) Technology Risks Regulation sets one of the Gulf's most specific penetration testing mandates for banks: semi-annual vulnerability assessment and penetration testing of infrastructure and network devices (section 9.1.1.5), plus two penetration testing exercises and two vulnerability assessments per year on applications (section 9.4.3), following OWASP, OSSTMM and SANS. For government, the National Information Assurance (NIA) Policy v2.0 requires an annual Security Assurance Plan that may include penetration testing (control IM 9) and independent pre-production testing (control SS 7). The QCB rules apply to all licensed banks (with parallel regulations for payment providers and insurers); the NIA Policy applies to government agencies. The National Cyber Security Agency (NCSA) oversees the national layer.

// 01 Who regulates cybersecurity in Qatar?

Two bodies matter for penetration testing. The Qatar Central Bank (QCB) regulates the financial sector — banks, payment service providers and insurers — and its cybersecurity rules are the most prescriptive in the country. The National Cyber Security Agency (NCSA), established in 2021, owns the national cybersecurity architecture: it holds the National Information Assurance Policy (previously issued by the Ministry of Transport and Communications and Q-CERT), classifies critical sectors, and publishes national data-classification and cloud-security policies. Which regime governs you depends on whether you are a financial institution, a government agency, or a critical-sector operator — and some organisations answer to more than one.

// 02 QCB penetration testing requirements for banks

The QCB Technology Risks Regulation is refreshingly explicit where many frameworks are vague — it fixes the frequency. Two sections carry the core testing mandate, and both require testing twice a year.

// QCB Technology RisksThe testing mandates

Section 9.1.1.5 (infrastructure & network): "Vulnerability assessment and penetration testing of infrastructure and network devices must be performed on a semi-annual basis as specified in the vulnerability assessment and penetration testing guidelines."

Section 9.4.3 (applications): a comprehensive vulnerability assessment using automated tools and manual techniques "at a minimum of two … on an annual basis" following OWASP/OSSTMM/SANS, and "The bank shall conduct two penetration testing exercises, or more frequently as needed, on an annual basis." Business-risk acceptance for open vulnerabilities is reviewed semi-annually.

Section 9.4.2 (application lifecycle): application security testing of web and mobile applications throughout the lifecycle — pre-implementation, post-implementation, and after major changes.

Read together, a Qatari bank must run semi-annual VAPT on its infrastructure and network, and two penetration tests plus two vulnerability assessments a year on its applications — with additional testing around every major application change. That is a materially heavier cadence than the annual testing many frameworks expect, and it should anchor any Qatari bank's testing calendar.

// 03 The NIA Policy for government

Outside the financial sector, the National Information Assurance (NIA) Policy v2.0 is Qatar's baseline. It is structured into governance-and-process controls and technical security controls across domains such as network, software, access and monitoring. Unlike the QCB rules, it does not carry a single "test every N months" control — instead, penetration testing is embedded within the assurance and software-security controls.

IM 9

Annual Security Assurance Plan

"The Incident Management coordinator is responsible for developing and executing an annual Security Assurance Plan. This may include activities such as penetration testing, audit of security procedures, and incident scenario testing." Penetration testing is named as an activity within a mandatory annual plan.

SS 7

Independent pre-production testing

"Software should be reviewed and/or tested for vulnerabilities before it is used in a production environment. Software SHOULD be reviewed and/or tested by an independent party and not by the developer." Independence is explicit.

So a Qatari government agency evidences the NIA Policy through an annual assurance plan that includes penetration testing, plus independent security testing of software before it goes live. The "independent party, not the developer" wording in SS 7 is worth noting — it rules out self-testing by the build team.

// 04 Who must comply

FrameworkApplies toTesting cadence
QCB Technology RisksLicensed banksSemi-annual VAPT + 2 pen tests/yr (apps)
QCB PSP Regulation (2022)Payment service providersSector cyber controls
QCB Insurance RegulationInsurersSector cyber controls
NIA Policy v2.0Government agenciesAnnual assurance plan (IM 9)
NCSA critical-sector standardsCritical national infrastructurePeriodic assessments

// 05 The NCSA national layer

Above the sector regulators, the National Cyber Security Agency develops Qatar's national cyber framework, classifies critical sectors, and issues cross-cutting policies — including a National Data Classification Policy (C0–C4 tiers) and a Cloud Security Policy. Critical-infrastructure operators are subject to periodic security assessments under this national layer. The detailed control text of the national framework is not fully public, so we describe the requirement functionally: critical-sector operators should expect to evidence periodic penetration testing and assessment, in addition to any sector-specific rules such as the QCB regulation. For a bank that is also designated critical infrastructure, that means satisfying both the QCB cadence and the NCSA assessment expectations — efficiently done by scoping one testing programme against both.

// 06 Frequently asked questions

Does Qatar require penetration testing for banks?

Yes. QCB requires semi-annual VAPT of infrastructure and network devices, and two penetration tests plus two vulnerability assessments a year on applications.

How often must banks test?

Twice a year — semi-annual infrastructure VAPT and two application penetration tests annually, following OWASP/OSSTMM/SANS, plus testing around major changes.

What does the NIA Policy require?

No single fixed frequency, but IM 9 requires an annual Security Assurance Plan that may include penetration testing, and SS 7 requires independent pre-production testing.

Who regulates it?

QCB for the financial sector; NCSA for the national framework, critical sectors and the NIA Policy.

// 07 Sources

Control references reflect the QCB Technology Risks Regulation and NIA Policy v2.0 as published. Confirm the current text for your institution before relying on this for a regulatory submission.

AH

Ankur H.

Security & Compliance Specialist, CyberFortify

Maps technical findings to the frameworks GCC regulators assess — QCB, the NIA Policy, SAMA, NCA ECC, CBB and the UAE frameworks — so one engagement satisfies several obligations.

Qatari bank due for semi-annual testing?

CyberFortify delivers the semi-annual VAPT and twice-yearly application penetration testing the QCB Technology Risks Regulation requires — following OWASP and OSSTMM, with findings mapped to the QCB and NIA control references your assessor expects.

Schedule scoping call → Financial-sector testing →